Android
This hub aggregates every CVE we track for Android, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
9,006
CVEs tracked
781
Critical
3,843
High
36
In CISA KEV
Severity distribution
MEDIUM4,115HIGH3,843CRITICAL781LOW267
Monthly trend
47
55
129
58
84
42
17
17
21
12
15
34
190
14
15
116
32
16
107
11
13
126
0
17
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Android.
- CVE-2026-21073Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.6.1
- CVE-2026-21072Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
- CVE-2026-21071Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
- CVE-2026-21070Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.4.6
- CVE-2026-21069Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
- CVE-2026-21068Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.7.8
- CVE-2026-21067Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
- CVE-2026-21066Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
- CVE-2026-21065Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.7.8
- CVE-2026-21064Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.5.5
- CVE-2026-21063Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.6.1
- CVE-2026-21062Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.3.3
- CVE-2026-21061Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.6.5
- CVE-2026-21060Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.4.6
- CVE-2026-21059Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.7.1
Product normalization is registry-driven with AI assist and human review. How it works